Get NIST-y

·S1 E34

Open Source Risk: How MSPs Decide What They Can Trust

August 25
47 mins

Episode Description

Open source is already in your stack, whether you deliberately installed it or not. In this ChannelCon 2026 talk, Jared lays out a practical way for MSPs to decide what deserves trust, what needs guardrails, and what needs to go.


Takeaways:

• Scope the risk by asking what the software touches and what happens if it breaks

• Check whether the project is actually alive, maintained, and prepared to handle security reports

• Look beyond the package itself to dependencies, SBOMs, and supply-chain risk

• Assign one clear owner to monitor approved software after the initial review


And one important reality check: commercial software is not automatically safer. Your vendors are using open source too.


Make sure to follow the podcast or ask your own questions at:

https://blacksmithinfosec.com/nisty/


Want to see the slides or get the extra content? That's all available at https://blacksmithinfosec.com/channelcon

See all episodes